13

Updated 4 Oct 2026

🕵️ Chapter 13 — Intrusion Detection System (IDS) Cheat Sheet


🗺️ Big Picture

Who attacks? → Intruder Classes & Skill Levels
How do they attack? → Attack Lifecycle (6 phases)
How do we detect? → IDS Types + Detection Approaches
Where do we deploy? → Sensor Placement
What tools? → SNORT Rules + Honeypots
How do we measure? → FP / FN Evaluation

1. Classes of Intruders

ClassMotivationMethodsSkill
Cyber CriminalsFinancial gainIdentity theft, credential theft, ransomware, data theftVaries
Activists (Hacktivists)Social/political causeWebsite defacement, DoS, data leaks for bad PROften low
State-Sponsored (APT)Espionage / sabotageLong-term persistent attacks, highly sophisticatedVery high
Classic HackersChallenge / reputationBuffer overflow research, exploring systemsVaries

APT = Advanced Persistent Threat

  • Advanced = high skill, complex techniques
  • Persistent = long-duration attack, stays hidden for months/years
  • Examples: government-sponsored groups from China, USA, UK, and allies

2. Intruder Skill Levels

LevelSkillsWho?
Apprentice (Script-kiddie)Uses existing attack toolkits only; doesn't understand how tools workLargest group; criminals, activists
JourneymanModifies/extends toolkits; uses newly found vulnerabilities; can adapt tools for othersAll intruder classes
MasterDiscovers brand-new vulnerability categories; writes new toolkits from scratchState-sponsored, elite hackers

🍔 Analogy: Apprentice = orders off the menu. Journeyman = tweaks the recipe. Master = invents the dish from scratch.

Easiest to defend against: Apprentice (uses known tools → known signatures) Hardest to defend against: Master (zero-day discoveries, custom tools)


3. Attack Lifecycle (Intruder Behavior)

① Target Acquisition & Info Gathering
        ↓
② Initial Access
        ↓
③ Privilege Escalation
        ↓
④ Information Gathering / System Exploit
        ↓
⑤ Maintaining Access
        ↓
⑥ Covering Tracks

Each Phase in Detail

PhaseWhat the attacker does
① ReconExplore corporate website, use dig/host/WHOIS/NMAP, send query emails to fingerprint mail server/OS
② Initial AccessBrute force CMS passwords, exploit vulnerable plugin, send spear-phishing emails with exploit links
③ Privilege EscalationScan for local exploits, install sniffers to capture admin passwords, use captured creds for higher access (Guest → Admin)
④ ExploitScan files for sensitive data, transfer large document batches to external server, reuse captured passwords across other servers
⑤ Maintain AccessInstall remote admin tool / rootkit with backdoor, disable or modify AV / IDS
⑥ Cover TracksUse rootkit to hide files, edit log files to erase intrusion entries

4. Key Definitions (RFC 2828)

Security Intrusion=unauthorized access attempt (or success)\boxed{\text{Security Intrusion} = \text{unauthorized access attempt (or success)}}

Intrusion Detection=monitor + analyze events→real-time/near-real-time warning\boxed{\text{Intrusion Detection} = \text{monitor + analyze events} \rightarrow \text{real-time/near-real-time warning}}


5. IDS — Core Concept

Core assumption: An intruder's behavior differs from a legitimate user's in detectable ways.

But there's always overlap between intruder and user profiles → causes:

  • False Positives — normal behavior flagged as suspicious
  • False Negatives — actual attack not detected

Three Logical Components of IDS

[Sensors] → collect data (traffic, system calls, logs)
    ↓
[Analyzers] → determine if intrusion occurred
    ↓
[User Interface] → view output / control system

6. IDS Types

TypeWhat it monitorsData Sources
HIDS (Host-based)A single host / serverSystem calls, audit logs, file integrity checksums, registry access
NIDS (Network-based)Network traffic (packet-by-packet)Network/transport/application layer packets
Distributed / HybridMultiple hosts + network (centrally correlated)Host agents + LAN monitor agents → Central Manager

📷 Analogy:

  • HIDS = CCTV inside a room (watching one host)
  • NIDS = CCTV at the corridor junction (watching all traffic passing)
  • Distributed = both cameras + a security room that correlates all footage

7. Why IDS Matters (3 Reasons)

  1. Detect + eject intruders quickly before damage occurs
  2. Acts as a deterrent — discourages attacks
  3. Collects attack intelligence — strengthens future defenses

8. IDS Requirements

RequirementDescription
Run continually24/7, no downtime
Fault tolerantSurvives system failures
Resist subversionCannot be easily disabled by attackers
Minimal overheadMust not degrade system performance
Policy-alignedReflects organization's security rules
AdaptiveUpdates as systems and user behaviors evolve
ScalableHandles large networks efficiently
Graceful degradationStill partially functions under stress
Dynamic reconfigurationUpdateable without full restart

9. Detection Approaches

Approach 1 — Anomaly Detection

  • Builds a baseline of normal user/system behavior over time
  • Flags significant deviations from baseline
  • Can detect: zero-day attacks, insider threats, unknown malware

💳 Analogy: Like a bank that knows your spending habits. If your card suddenly gets used overseas at 3 AM → auto-blocked. It doesn't need to know the exact fraud type — it just knows it's unusual.

Sub-approaches:

Sub-approachHow it worksExample
StatisticalUnivariate, multivariate, or time-series models of normal metricsJohn always logs in 9–5; login at 2 AM → flag
Knowledge-basedExpert rules model what legitimate behavior looks likeRule: admin should never run rm -rf /interactively
Machine LearningTrains a model on labeled data to classify normal vs. abnormalCan also predict, not just classify (threat intelligence)

Anomaly Detection Example:

IDS learns: john logs in 9am–5pm, uses vim/firefox, never touches /etc/passwd
→ Suddenly: john runs bash → sudo cp /etc/shadow /tmp/
→ IDS flags: unexpected sudo + outside normal hours + sensitive file access 🚨

Real-World Tools

ToolTypeNotes
Wazuh / OSSECHIDSLogin, command, file access anomalies
Snort + ML moduleNIDSAbnormal packet patterns (DoS, C2 beaconing)
Zeek (formerly Bro)NIDSDNS, HTTP, SSH behavior anomalies
Security OnionHybridLogs + PCAPs + ML anomaly detection
Suricata + Unsupervised MLNIDSFlow features (packet size, timing) for unknown malware

Approach 2 — Signature / Heuristic Detection

  • Matches known malicious patterns against traffic or system data
  • Must be specific enough to minimize false alarms
  • Widely used in anti-virus, traffic proxies, NIDS

Rule-Based Heuristic

  • Uses rules based on known exploits or known weaknesses
  • Can also flag suspicious behavior within normal patterns
  • SNORT = prime example

🛡️ Analogy: Like a spam filter — it knows what spam patterns look like. But it cannot detect brand-new spam it's never seen before.


Anomaly vs. Signature — Comparison

Signature DetectionAnomaly Detection
ProsSimple, fast, low overheadAdaptive, detects unknown attacks (zero-day)
Cons❌ Cannot detect new/unknown patternsSlower, higher overhead (needs training/baseline)
Best forKnown attack types, policy violationsDoS, scanning, worms, insider threats

📌 If forced to choose between FP and FN for IDS: prefer False Positive — better to flag a normal event for review than to miss a real attack.


10. Evaluation of IDS — FP & FN

TypeNameWhat happensConsequence
False Positive"Not but In" (normal flagged as attack)IDS alerts on legitimate activityWastes analyst time; alert fatigue
False Negative"Yes but Out" (attack not detected)IDS misses real malicious activityAttack succeeds undetected ⚠️

✈️ Airport Analogy:

  • False Positive = pulling an innocent passenger aside for screening
  • False Negative = letting someone with a weapon walk through

Goal: minimize both FP and FN — but FN is more dangerous\boxed{\text{Goal: minimize both FP and FN — but FN is more dangerous}}


11. IDS Placement — Before or After Firewall?

PositionProsCons
After firewallLess noise (FW already filters obvious threats); lower IDS processing load; focuses on real threatsMisses attacks that firewall lets through
Before firewallFull visibility of all raw inbound traffic; better for ML training (more data)High volume → performance tradeoff
Hybrid (both)Defense in Depth; covers blind spotsMore complex, more resources

12. Host-Based IDS (HIDS)

  • Installed on the host (server or endpoint)
  • Can use anomaly or signature approach
  • Primary purpose: detect intrusions, log suspicious events, send alerts
  • Can detect both external and internal intrusions

HIDS Data Sources

  • System call traces
  • Audit / log file records
  • File integrity checksums (detect tampered files)
  • Registry access (Windows)

13. Distributed IDS Architecture

Three modules working together:

ModuleRole
Host Agent ModuleBackground process on each host; collects security events; transmits to central manager
LAN Monitor Agent ModuleAnalyzes LAN traffic; reports to central manager
Central Manager ModuleReceives all reports; processes and correlates across sources to detect intrusions

Agent Flow:

OS Audit Function
      ↓
Filter for Security-Relevant Events
      ↓
Reformat → Host Audit Record (HAR)
      ↓
Logic Module ←→ Templates
      ↓
Analysis Module ←→ Central Manager
      ↓ (Alerts sent up)

14. Network-Based IDS (NIDS)

  • Monitors traffic at selected network points, packet by packet, in real/near-real time
  • Examines: network / transport / application layer protocols
  • Components: Sensors + Management Server(s) + Management Console(s)

NIDS Sensor Modes

ModeHow it worksCan Block?Risk
Inline SensorInserted directly in network path; all traffic passes through✅ Yes (real-time)Can interrupt traffic if sensor fails
Passive SensorMonitors a copy of traffic via SPAN port or network tap❌ No (detect + alert only)May miss packets under heavy load

🚦 Analogy:

  • Inline = a guard standing at the gate — can physically stop you
  • Passive = a CCTV camera — records everything but can't stop anyone

Deep Packet Inspection (DPI):

  • Normal firewall checks only the packet header
  • Inline NIDS with DPI checks the payload too
  • To bypass DPI: encrypt the payload (e.g., HTTPS) → DPI can't read it

NIDS Sensor Deployment Positions

Internet
   ↓
External Firewall
   ↓ ← Sensor [2] — between internet and external firewall (sees raw traffic)
LAN Switch / Router ← Sensor [1] — between external FW and internal network
   ├── Service Network (Web, Mail, DNS)
   ├── Internal Servers ← Sensor [3] — catches lateral movement
   └── Workstation Networks ← Sensor [4] — catches endpoint attacks

Intrusion Detection Techniques by Attack Type

TechniqueBest For
Signature DetectionApp/transport/network layer recon, unexpected services, policy violations
Anomaly DetectionDoS attacks, scanning, worms

What NIDS Logs

  • Timestamp, connection/session ID, event/alert type, severity
  • Source/destination IP + ports
  • Network/transport/application layer protocols
  • Bytes transmitted, decoded payload, state info

15. Honeypots

Decoy systems — fake targets designed to:

  • Lure attackers away from real systems
  • Collect intelligence about attacker behavior and tools
  • Keep attacker engaged → give admins time to respond

🪤 Analogy: A trap with bait — the burglar wastes time on a fake safe while you track them.

Key properties:

  • Filled with fabricated (fake) data — legitimate users would never access it
  • No production value → any incoming connection = likely probe/attack
  • Outbound traffic from honeypot = system likely compromised

Honeypot Types

TypeDescriptionRisk
Low InteractionSoftware emulating services — not a real systemLow; limited attacker movement
High InteractionReal OS + real services — very realistic; keeps attacker longerHigher; if fully compromised, could be used to attack other systems

Honeypot Deployment Positions

PositionLocationPurpose
Position 1Before external firewallFaces internet directly; catches opportunistic scanners
Position 2DMZ / service networkCatches attacks targeting public-facing services
Position 3Internal networkDetects insider threats and lateral movement

16. SNORT

Open source, lightweight, configurable HIDS/NIDS

  • Deployable on most nodes (host, server, router)
  • Low memory + CPU usage
  • Easily configured by sysadmins

SNORT Architecture

Packet → Packet Decoder → Detection Engine → Logger
                                           → Alerter
ComponentRole
Packet DecoderProcesses captured packets; isolates protocol headers at all layers (data link → application)
Detection EngineMatches each packet against all rules; first match triggers action; unmatched = discarded
LoggerStores matching packets in human-readable or compact binary format
AlerterSends alert to file, UNIX socket, or database; can be disabled for testing

SNORT Rule Format

[Action] [Protocol] [Src IP] [Src Port] [Direction] [Dst IP] [Dst Port] ([Options])

Example:

alert tcp any any -> 192.168.1.0/24 80 (msg:"HTTP scan detected"; content:"GET"; nocase;)

Direction Operators

OperatorMeaning
->One-way (source → destination)
<>Bidirectional

SNORT Rule Actions

ActionWhat happens
alertGenerate alert + log packet
logLog only (no alert)
passIgnore packet
activateAlert + activate a dynamic rule
dynamicIdle until triggered by activate → then acts as log
dropiptables drop + log
rejectiptables drop + log + send TCP reset (or ICMP unreachable for UDP)
sdropiptables drop — no log (silent drop)

Rule Options — 4 Categories

CategoryPurposeKey Options
meta-dataInfo about the rule (no effect on detection)msg, reference, classtype
payloadSearch inside packet payloadcontent, depth, offset, nocase
non-payloadCheck non-payload fieldsttl, id, dsize, flags, seq, icmp-id
post-detectionTriggers after rule matcheslogto, session

Key Option Details

OptionWhat it checksUse Case
contentCase-sensitive pattern in payloadLook for GET /admin in HTTP
depthHow far into packet to searchSearch only first 100 bytes
offsetWhere to start searchingSkip header bytes
nocaseCase-insensitive content matchMatch regardless of capitalization
ttlIP time-to-live valueDetect traceroute attempts
idIP ID fieldValue 31337 = hacker favorite
dsizePayload sizeDetect buffer overflow attempts (oversized payload)
flagsTCP flag settingsSYN scan, FIN scan detection
seqTCP sequence numberDetect specific malicious sequences
icmp-idICMP ID valueDetect covert channel tools (e.g., stacheldraht DDoS)
logtoCustom log fileRoute specific alerts to separate file
sessionExtract TCP session user dataCapture telnet, FTP, web session content

IDS Rule Breakdown Example (Linux auditd)

-a always,exit -F arch=b64 -S execve -F exe=/usr/sbin/tcpdump -k sniffing
SegmentMeaning
-a always,exitAudit every invocation of the syscall on exit
-F arch=b64Target 64-bit architecture (use b32 for 32-bit)
-S execveWatch the execve syscall (triggered when any process executes)
-F exe=/usr/sbin/tcpdumpOnly trigger when the executed binary is exactly tcpdump
-k sniffingAdds tag sniffing for easy filtering: ausearch -k sniffing

17. IETF IDS Standards (2007 RFCs)

RFCNameDescription
RFC 4766Intrusion Detection Message Exchange RequirementsDefines requirements for IDMEF format + communication protocol
RFC 4765Intrusion Detection Message Exchange Format (IDMEF)Data model for IDS-exported info; implemented in XML
RFC 4767Intrusion Detection Exchange Protocol (IDXP)App-level protocol for exchanging data between IDS entities; supports mutual auth, integrity, confidentiality

🗂️ Summary Table

TopicKey Points
Intruder ClassesCyber criminals (money), Hacktivists (cause), APTs (state), Classic hackers (challenge)
Skill LevelsApprentice (script-kiddie) → Journeyman → Master
Attack LifecycleRecon → Initial Access → Priv Esc → Exploit → Maintain → Cover Tracks
IDS TypesHIDS (one host), NIDS (network), Distributed (multi-sensor + central correlation)
Detection ApproachesAnomaly (baseline/ML) — detects unknowns; Signature (rules/patterns) — fast, known only
NIDS Sensor ModesInline (can block, adds latency) vs. Passive (monitor only, SPAN port)
FP vs FNFP = normal flagged (alert fatigue); FN = real attack missed (worse!)
HoneypotsLow interaction (emulated) vs. High interaction (real system, more risk)
SNORTDecoder → Detection Engine → Logger/Alerter; rule-based; 8 actions; 4 option categories

⚡ Key Facts to Remember

FactDetail
APT = Advanced Persistent ThreatState-sponsored, high skill, long-duration, stays hidden
Largest intruder groupApprentices / Script-kiddies
IDS core assumptionIntruder behavior differs from legitimate user behavior (but overlap exists)
FP preferred over FNBetter to review a false alarm than miss a real attack
Passive NIDS = SPAN portCopies traffic; cannot block
Inline NIDS = on the pathCan block; adds latency; risk of disruption if fails
DPI = Deep Packet InspectionChecks payload, not just header; can be bypassed by encryption
Honeypot outbound trafficAny outbound = likely compromised
High-interaction honeypot riskIf attacker escapes it, they can attack real systems
SNORT sdropSilently drops — no log, attacker doesn't know it was blocked
id = 31337Classic hacker signature in IP ID field
dsize ruleUsed to detect buffer overflow (oversized payload)